Cybersecurity

Anthropic Reorganizes Cyber Verification Program into Three Levels for Access to Its Advanced Models

Anthropic has combined its Cyber Verification Program and Project Glasswing into a single system that gives security teams tiered access to Claude models, with verification requirements and controls varying according to the level of use. The program covers incident response, penetration testing, and critical-systems testing, while continuing to prohibit uses that could cause widespread harm.

2026-10-07
3 min read
2 views
certi.news
Anthropic Reorganizes Cyber Verification Program into Three Levels for Access to Its Advanced Models

Anthropic announced the restructuring of its Cyber Verification Program (CVP), merging it with Project Glasswing into a single offering with three levels of access to its most capable models. The move is based on a dual problem: models that help defenders discover and fix vulnerabilities can also provide capabilities useful to attackers.

Claude models generally available, including Claude Opus 5.5, Sonnet 5.5, and Fable 5.1, come with controls that prevent most cyber operations. Under the new program, the three levels include Opus 5.5, Sonnet 5.5, Mythos 5.1, and future models, but each level has different verification requirements and operational controls.

Three Levels for Cyber Use

Defense Access is intended for security operations center activities and incident response, malware reverse engineering, and vulnerability analysis and validation. Security teams defending their own systems, critical infrastructure operators, small security companies, open-source project maintainers, and individual researchers with a track record of reporting vulnerabilities may apply. Anthropic says it aims to respond to applications within a few days.

Red Team Access adds authorized penetration testing and red-team exercises, with operations limited to systems the applicant is authorized to test. Procedures that could cause physical harm or widespread disruption, such as deploying ransomware, remain prohibited in real time. This level is available only to organizations, and its review is expected to take a few weeks, with qualified applicants temporarily granted Defense Access permissions.

Specialized Access has the fewest cyber barriers, but is limited to a small number of organizations authorized to test sensitive systems, such as power grids, aviation systems, telecommunications networks, and interbank transfer infrastructure. Anthropic reviews applications for this level in cooperation with the U.S. government, while current Glasswing members move to it.

Indicators of the Program's Impact

Anthropic said Glasswing partners discovered at least 129,000 validated vulnerabilities between April and July, while the company's open-source scan produced an additional 5,500 vulnerabilities between April and October. More than 33,000 of them were classified as high or critical severity. The company estimates that the actual impact may be at least five times greater, because the figures cover only a sample of participants.

What Changes in Practice?

The new design turns access to cyber capabilities from separate exceptions into a unified path based on the organization's identity, the scope of authorization, and the sensitivity of the targeted systems. In return, participating organizations must agree to data retention to enable Anthropic to monitor misuse. The company intends to make Enterprise Frontier Safeguards available later in the fall, allowing eligible customers to store data in a cloud infrastructure they control. Until then, organizations with no-data-retention access to Fable 5.1 or Mythos 5.1 can use CVP with this configuration.

CVP is available on Claude Platform, Google Cloud Vertex AI, and Microsoft Foundry, while its availability on Amazon Bedrock is limited to customers eligible for Enterprise Frontier Safeguards. Current members are automatically evaluated for access to the new models, while retaining their existing settings for previous models.

News source
c
Author

certi.news

In the same category

You may also like

View all news